Legal

Privacy Policy

This policy explains what personal information Meradomo collects, why, who we give it to, and the rights you have over it.

Effective 17 July 2026 · Last updated 17 July 2026

The short version. We cannot read the data your apps send through Meradomo — it is sealed with a key that only your computer holds. We do know your email address, which of your apps was reached, and when. We do not sell or share your personal information, and we never have.

This summary is for convenience. The sections below govern.

1. Who we are

Meradomo is a product of Cerevox, Inc. ("Cerevox", "we", "us", "our"), a Delaware corporation. Cerevox, Inc. is the business responsible for the personal information described in this policy, and is the "business" for purposes of the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (together, the "CCPA").

Our mailing address is 536 Middlebury Dr., Sunnyvale, CA 94087. You can reach us at privacy@meradomo.com.

2. Scope

This policy applies to personal information we collect through the Meradomo website (meradomo.com and its subdomains), the Meradomo desktop application, and the Meradomo account service (together, the "Service").

It does not apply to the applications you choose to run on your own computer and make available through Meradomo. Those applications run on your machine, hold their data on your machine, and are governed by their own terms — including applications published by us, such as Notewell and Keyhold, and applications published by third parties. We do not receive the data inside them.

3. Personal information we collect

The table below lists the categories of personal information we have collected in the preceding twelve months, using the categories defined in Cal. Civ. Code § 1798.140(v).

CategorySpecific informationPurpose
Identifiers Email address; display name; the name you claim for your address; account identifier; device identifiers; Internet Protocol (IP) address. Create and secure your account; sign you in; route visits to your computer; prevent abuse.
Commercial information Subscription plan, subscription status, billing period, and records of transactions. We do not collect or store your payment card details — our payment processor does. Provide and bill the subscription; support; tax and accounting.
Internet or other electronic network activity information Connection metadata: the address requested (which reveals which of your applications was reached), timestamps, amount of data transferred, and whether your computer was online. Website and application logs. Deliver the Service; diagnose faults; detect abuse and protect the Service.
Professional or employment information Only if you volunteer it — for example, in a support message or a developer application. Respond to you.

We do not collect sensitive personal information as defined by the CCPA (Cal. Civ. Code § 1798.140(ae)). We do not collect biometric information, precise geolocation, racial or ethnic origin, religious beliefs, health information, or the contents of your mail, email, or text messages. Because we do not collect sensitive personal information, the right to limit its use and disclosure does not arise.

4. What we do not collect

This section is unusual for a privacy policy, but it is the most important thing we can tell you.

Meradomo carries data between your computer and your devices. That data is sealed using a private key that is generated on your computer and never transmitted to us. Our servers move sealed bytes they hold no key for.

As a result we do not collect, receive, log, or store:

This is a property of how the Service is built, not a policy choice we could quietly reverse. The record of who reached which of your applications is written on your own computer, where you can read it and we cannot.

One narrow exception, for completeness: when your computer is offline, our servers briefly hold a short-lived key for your address solely in order to display a static "this computer is asleep" notice to visitors. No data of yours is in transit at that time, and that code path cannot forward a request anywhere. It is described in full on our security page.

5. Where we get it

6. How we use it

We use personal information to: provide, maintain, and secure the Service; authenticate you; route visits to your computer; take payment and manage subscriptions; send service messages (sign-in links, billing notices, and material changes); respond to support requests; detect, investigate, and prevent fraud, abuse, and security incidents; and comply with law.

We do not use your personal information to build advertising profiles, and we do not perform profiling that produces legal or similarly significant effects.

7. Who we disclose it to

We disclose personal information for business purposes to a small number of service providers who are contractually bound to use it only to perform services for us:

RecipientPurposeCategories disclosed
Microsoft Azure Hosting the Service; sending transactional email from our own domain Identifiers; internet activity information
Stripe, Inc. Payment processing and subscription billing Identifiers; commercial information

We may also disclose personal information: to comply with a law, regulation, subpoena, or lawful government request; to enforce our Terms of Service; to protect the rights, property, or safety of Cerevox, our users, or the public; and to a successor entity in connection with a merger, acquisition, or sale of assets, in which case we will require the successor to honour this policy or give you notice and a choice before your information becomes subject to a materially different policy.

Because we cannot read the content that passes through the Service, we cannot produce it in response to a legal demand. We can only produce what we have, which is described in section 3.

8. No sale, no sharing, no targeted advertising

We do not sell your personal information, and we have not sold it in the preceding twelve months. We do not "share" it for cross-context behavioural advertising as that term is defined by the CCPA, and we have not done so in the preceding twelve months. We do not disclose the personal information of consumers we know to be under 16 for such purposes.

We do not serve advertising on the Service, and we do not permit third parties to collect personal information about you across sites through the Service.

9. Analytics and campaign measurement

We need to know whether anyone is finding this website. We measure it with software we run ourselves, on our own servers, reachable only at our own address. No third party is involved: no outside code runs on these pages, and nothing about your visit is sent anywhere else. The counting happens on machines we control, and the numbers stay there.

We set no cookies for measurement. That is why this site shows you no cookie banner — there is nothing to consent to, because nothing is being stored on your device.

What we record is the visit, not the visitor:

When we announce something — on a discussion site, in a newsletter, on social media — the links we publish carry a plain campaign name, visible in your address bar, so we can tell which announcement people actually read. That name describes the announcement. It does not describe you, and it is the same for everyone who follows the same link.

Our analytics records contain no Internet Protocol (IP) address, no browser or device fingerprint, and no identifier that persists from one visit to the next. This is a property of the records themselves: there is no field in which such a thing could be written. As a result we cannot assemble a browsing history for any individual, and neither can anyone who compels us to hand the records over.

Raw records are kept for no more than 30 days. After that they are reduced to daily totals — how many visits a page received on a given day — which identify no one and which we keep so we can see whether the product is growing.

Sections 8 and 13 apply here unchanged and without exception: none of this follows you to another website, and none of it is shared with or sold to anybody.

10. How long we keep it

We keep each category only as long as needed for the purpose it was collected for:

CategoryRetention
Account information (email, name, claimed name)For the life of your account, then deleted within 30 days of account deletion.
Device recordsUntil you remove the device, or your account is deleted.
Sign-in linksMinutes — they expire shortly after issue and are single-use.
SessionsUntil expiry or sign-out.
Connection metadata and operational logsNo more than 30 days, then deleted or aggregated so it no longer identifies you.
Billing and transaction recordsAs long as required by tax and accounting law — generally seven years.

Where we are required to retain information to comply with a legal obligation, resolve a dispute, or enforce our agreements, we retain it for that period and no longer.

11. Your California privacy rights

If you are a California resident, the CCPA gives you the following rights:

12. How to exercise your rights

Email privacy@meradomo.com from the address associated with your account, or write to us at the postal address in section 1. Meradomo is an internet-only business and has no physical customer-facing location, so email is the primary method for submitting requests.

Verification. To protect you, we must verify that you are who you say you are before we act. We do this by confirming control of the email address on the account — normally by sending a link to it. For requests to delete or to receive specific pieces of personal information, we may ask for additional confirmation appropriate to the sensitivity of the request. We will not ask you for more information than is necessary, and we will not use anything you give us for verification for any other purpose.

Timing. We confirm receipt within 10 business days and respond within 45 calendar days. If we need more time we will tell you why and take no more than 90 calendar days in total.

Authorized agents. You may use an authorized agent. We will ask for written permission signed by you and will still verify your identity directly, unless your agent provides a valid power of attorney under Cal. Prob. Code §§ 4000–4465.

Appeals. If we decline your request, our response will explain why. You may reply to ask us to reconsider, and you may complain to the California Privacy Protection Agency or the California Attorney General.

13. Do Not Track and opt-out preference signals

Because we do not sell or share personal information and do not track you across third-party sites, there is nothing for an opt-out preference signal to switch off. We honour the Global Privacy Control (GPC) signal in the sense that our practices already match what it asks for. Web browsers also offer a "Do Not Track" signal; there is no common standard for how to respond to it, and we do not track you regardless of the setting.

14. California "Shine the Light"

California Civil Code § 1798.83 lets California residents ask us once a year about personal information we disclosed to third parties for their own direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

15. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us personal information, contact privacy@meradomo.com and we will delete it. You must be at least 18 to hold a Meradomo account (see our Terms of Service).

16. Security

We use reasonable security procedures and practices appropriate to the nature of the personal information we hold. Device credentials are stored only as irreversible hashes, never in a form we could reuse. Sign-in links are short-lived and single-use. Traffic between your computer and your devices is sealed end to end with a key we never possess.

No method of transmission or storage is completely secure, and we do not claim otherwise. What we can say is narrower and stronger: the data we cannot receive cannot be exposed by us. Our security page and our public threat model set out both the protections and their limits.

17. Users outside the United States

We operate in the United States and process personal information there. If you use the Service from outside the United States, you understand that your personal information will be transferred to and processed in the United States, where data protection law may differ from that of your country.

If you are in the European Economic Area or the United Kingdom, our legal bases for processing are: performance of a contract (providing the Service you asked for, and billing it); legitimate interests (securing the Service and preventing abuse); and compliance with a legal obligation. You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. Use the contact details in section 19.

18. Changes to this policy

We may update this policy. When we do, we change the "last updated" date above and post the new version here. If a change materially affects how we treat personal information already collected, we will give you notice by email to the address on your account before it takes effect, and where the law requires it we will ask for your consent.

19. Contact us

Cerevox, Inc.
536 Middlebury Dr., Sunnyvale, CA 94087
privacy@meradomo.com

Under California Civil Code § 1789.3, users of the Service are entitled to the following consumer rights notice: the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs may be contacted in writing at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.